Node.js Experimental Permission Model Vulnerabilities Identified
First seen 18 Feb 2026, 13:23 UTC
•
•44.0
Export
Article Content
Browse articles
Two vulnerabilities have been identified in the experimental permission model of Node.js 20 and 21. CVE-2024-21890 reveals that wildcards in file paths can lead to unintended access, while CVE-2024-21896 allows for path traversal attacks through monkey-patching Buffer internals. These issues affect all users utilizing the experimental feature.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2024-02-20
CVE-2024-21890 published
2024-02-20
CVE-2024-21896 published
2026-02-18
Information published about vulnerabilities
More articles in this cluster
Continue Reading
CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers
CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action
Critical RCE Vulnerability in n8n Affects Over 100K Servers
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud